CVE-2026-93871
MEDIUM
NVD
CVSS Score
5.4
Severity
MEDIUM
Published
Sep 18, 2026
Vendor
unknown
Description
Cotonti through 1.0.0 fails to validate redirect destinations in page bodies prefixed with redir:, allowing authenticated users with page creation or edit permissions to store redirects to arbitrary external hosts. Attackers can craft pages on trusted domains that redirect visitors to malicious sites for phishing attacks without administrative privileges.
References
- https://github.com/Cotonti/Cotonti
- https://github.com/Cotonti/Cotonti/blob/1.0.0/modules/page/inc/page.main.php
- https://github.com/Cotonti/Cotonti/issues/1893
- https://github.com/Cotonti/Cotonti/pull/1901
- https://www.vulncheck.com/advisories/cotonti-through-1.0.0-stored-open-redirect-via-page-redir-prefix